Known vulnerabilities in Tenable Nessus
Vendor:
Tenable Network Security
Software:
Tenable Nessus
Software CPE:
cpe:2.3:a:tenable_network_security:tenable_nessus:*:*:*:*:*:*:*:*
Website:
https://www.tenable.com/
Total vulnerabilities:
104
Public exploits:
12
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
10.12.1
10.12.0
10.11.3
10.10.3
10.11.2
10.10.2
10.8.6
10.10.1
10.10.0
10.11.1
10.9.6
10.11.0
10.9.5
10.9.4
10.9.3
10.9.2
10.9.1
10.9.0
10.8.5
10.8.4
10.8.3
10.8.2
10.8.1
10.8.0
10.7.6
10.7.5
10.7.4
10.7.3
10.7.2
10.7.1
10.7.0
10.6.4
10.6.3
10.5.7
10.6.2
10.6.1
10.5.6
10.5.5
10.6.0
10.5.4
10.5.3
10.5.2
10.5.1
10.4.3
8.15.9
10.5.0
8.15.8
10.4.2
8.15.7
10.4.1
10.3.2
10.4.0
10.3.1
8.15.6
10.3.0
10.2.0
8.15.5
10.1.2
8.15.4
10.1.1
8.15.3
10.1.0
10.0.2
10.0.1
10.0.0
8.15.2
8.15.1
8.15.0
8.14.0
8.13.2
8.13.1
8.13.0
8.12.1
8.12.0
8.11.1
8.11.0
8.10.1
8.10.0
8.9.1
8.9.0
6.12.0
8.8.0
8.7.2
8.7.1
8.7.0
6.12.1
8.6.0
7.2.3
7.1.5
8.5.2
8.5.1
8.5.0
8.4.0
8.3.2
8.3.1
8.3.0
8.2.3
8.2.2
8.2.1
8.2.0
8.1.2
8.1.1
8.1.0
8.0.1
8.0.0
7.2.2
7.2.1
7.2.0
7.1.4
7.1.3
7.1.2
7.1.1
7.1.0
6.11.3
6.11.2
6.11.1
6.11.0
6.10.9
6.10.8
6.10.7
6.10.6
6.10.5
6.10.4
6.10.3
6.10.2
6.10.1
6.10.0
6.9.1
6.7.0
6.6.2
6.6.1
6.6.0
6.5.6
6.5.5
6.5.4
6.5.3
6.5.2
6.5.1
6.5.0
6.4.3
6.4.2
6.4.1
6.4.0
6.3.7
6.3.6
6.3.5
6.3.4
6.3.3
6.3.2
6.3.1
6.3.0
6.2.1
6.2.0
6.1.2
6.1.1
5.2.12
5.2.11
5.2.10
5.2.9
5.2.8
5.2.7
5.2.6
5.2.5
5.2.4
5.2.3
5.2.2
5.2.1
7.0.3
7.0.2
7.0.1
7.0.0
6.9.3
6.9.2
6.9.0
6.8.1
6.1.11
6.1.0
6.0.2
6.0.1
6.0.0
6.8.0
Vulnerabilities (104)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU135965 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2026-57587 |
CWE-89 | Medium | 10.12.1 | 30.06.2026 |
SB2026063047 |
||
| #VU135966 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2026-57588 |
CWE-89 | Low | 10.12.1 | 30.06.2026 |
SB2026063047 |
||
| #VU123484 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-3493 |
CWE-22 | Medium | 10.10.3, 10.11.3 | 03.03.2026 |
SB2026030359 |
||
| #VU122268 - Integer overflow CVE-2026-25210 |
CWE-190 | High | 10.10.2, 10.11.2 | 03.02.2026 |
SB2026020364 SB20260205121 SB2026020611 and 22 more |
||
| #VU122267 - NULL Pointer Dereference CVE-2026-24515 |
CWE-476 | Medium | 10.10.2, 10.11.2 | 03.02.2026 |
SB2026020364 SB2026020367 SB2026020368 and 18 more |
||
| #VU117878 - Type confusion CVE-2025-11731 |
CWE-843 | Medium | 10.8.0, 10.8.1, 10.8.2, 10.8.3, 10.8.4, 10.8.5, 10.8.6, 10.9.6, 10.11.1 | 31.10.2025 |
SB2025103161 SB2025103165 SB2025103167 and 10 more |
||
| #VU117356 - Use After Free CVE-2025-10911 |
CWE-416 | Medium | 10.8.0, 10.8.1, 10.8.2, 10.8.3, 10.8.4, 10.8.5, 10.8.6, 10.9.6, 10.11.1 | 17.10.2025 |
SB2025101756 SB2025101762 SB2025101763 and 24 more |
||
| #VU115751 - Resource exhaustion CVE-2025-59375 |
CWE-400 | Medium | 10.8.0, 10.8.1, 10.8.2, 10.8.3, 10.8.4, 10.8.5, 10.8.6, 10.9.6, 10.11.1 | 17.09.2025 |
SB2025091783 SB2025091789 SB2025091790 and 107 more |
||
| #VU113533 - Use After Free CVE-2025-7425 |
CWE-416 | High | 10.8.0, 10.8.1, 10.8.2, 10.8.3, 10.8.4, 10.8.5, 10.8.6, 10.9.6, 10.11.1 | 31.07.2025 |
SB2025073137 SB2025073144 SB2025073053 and 56 more |
||
| #VU112071 - Permissions, Privileges, and Access Controls CVE-2025-36630 |
CWE-264 | Low | 10.8.5 | 01.07.2025 |
SB2025070116 |
||
| #VU111225 - Integer overflow CVE-2025-6021 |
CWE-190 | High | 10.8.0, 10.8.1, 10.8.2, 10.8.3, 10.8.4, 10.8.5, 10.8.6, 10.9.6, 10.11.1 | 17.06.2025 |
SB2025061921 SB2025062408 SB2025062747 and 63 more |
||
| #VU111224 - Stack-based buffer overflow CVE-2025-6170 |
CWE-121 | High | 10.8.0, 10.8.1, 10.8.2, 10.8.3, 10.8.4, 10.8.5, 10.8.6, 10.9.6, 10.11.1 | 17.06.2025 |
SB2025061728 SB2025071874 SB2025071875 and 12 more |
||
| #VU111223 - Type confusion CVE-2025-49796 |
CWE-843 | Medium | 10.8.0, 10.8.1, 10.8.2, 10.8.3, 10.8.4, 10.8.5, 10.8.6, 10.9.6, 10.11.1 | 17.06.2025 |
SB2025061728 SB2025070832 SB20250709112 and 84 more |
||
| #VU111221 - Use After Free CVE-2025-49794 |
CWE-416 | Medium | 10.8.0, 10.8.1, 10.8.2, 10.8.3, 10.8.4, 10.8.5, 10.8.6, 10.9.6, 10.11.1 | 17.06.2025 |
SB2025061728 SB2025070832 SB20250709112 and 65 more |
||
| #VU105946 - Use After Free CVE-2025-24855 |
CWE-416 | High | 10.8.5 | 21.03.2025 |
SB2025031964 SB2025032154 SB2025032155 and 63 more |
||
| #VU105879 - Use After Free CVE-2024-55549 |
CWE-416 | High | 10.8.0, 10.8.1, 10.8.2, 10.8.3, 10.8.4, 10.8.5, 10.8.6, 10.9.6, 10.11.1 | 19.03.2025 |
SB2025031964 SB2025031965 SB2025032155 and 69 more |
||
| #VU105723 - Stack-based buffer overflow CVE-2024-8176 |
CWE-121 | High | 10.8.0, 10.8.1, 10.8.2, 10.8.3, 10.8.4, 10.8.5, 10.8.6, 10.9.6, 10.11.1 | 14.03.2025 |
SB2025031426 SB2025031429 SB2025031430 and 105 more |
||
| #VU96899 - Integer overflow CVE-2024-45492 |
CWE-190 | High | 10.7.6, 10.8.3 | 05.09.2024 |
SB20240905100 SB20240905101 SB20240905102 and 108 more |
||
| #VU96898 - Integer overflow CVE-2024-45491 |
CWE-190 | High | 10.7.6, 10.8.3 | 05.09.2024 |
SB20240905100 SB20240905101 SB20240905102 and 106 more |
||
| #VU96744 - Type confusion CVE-2024-6119 |
CWE-843 | Medium | 10.7.6, 10.8.3 | 03.09.2024 |
SB2024090364 SB2024090365 SB2024090384 and 99 more |
Showing elements 1 - 20 out of 104